Blog
Running AI security models in private cloud and air-gapped environments
How to run capable AI for security work inside a private cloud or air-gapped network, without sending systems, credentials, or findings to a hosted API.
The strongest AI for security work is delivered through hosted APIs. For a private cloud or an air-gapped network, that is a problem. Using a hosted model means the systems under test, the credentials in scope, and the findings the model produces all leave the environment. For teams with sovereignty or compliance requirements, that rules out the models they would otherwise want to use.
The result is a gap. The capable AI runs somewhere you cannot send your data, and the AI you can run inside your boundary gives up capability. Closing that gap is the point of a specialized cyber model you can deploy where the work happens.
Why in-boundary deployment matters for security AI
Security work is exactly the work you least want to send out. A model doing vulnerability discovery reads source, touches running systems, and handles credentials and proof of exploitation. In a regulated bank, a defense contractor, or any environment with data residency rules, that content cannot go to a third-party API.
Hosted providers add a second constraint. Their usage policies restrict categories of security work, so a model that looks capable in a demo may refuse the offensive analysis an incident actually requires. A model you run yourself does not carry that restriction.
What to look for in a model you can run yourself
Three properties matter, and they are separate questions.
Capability. General models are trained for general tasks. A model built and evaluated specifically for cybersecurity finds and validates vulnerabilities that a general model misses, and it does so at lower cost per task. Ask how the model was trained and how its capability is measured.
Deployment. The model has to run inside your boundary, whether that is on-premises, in a private cloud, or fully air-gapped, with no data egress and no third-party retention. These are properties of how the model is deployed, so confirm them against your actual environment.
Hardware. A model that runs in your environment runs on your hardware, which in most enterprises means your own NVIDIA GPUs. A model tuned to run well on the hardware you already operate is cheaper to run and easier to scale.
How Basin deploys
Basin is Submersion's specialized cybersecurity model. It runs inside the customer's environment, on-premises, in a private cloud, or air-gapped, on the customer's own hardware. The systems it tests and the findings it produces stay inside the boundary.
Its capability is proven in the open rather than asserted. Basin discovers real vulnerabilities in widely used software, and after each is patched, the model rediscovers it with no prior knowledge of the bug. That blind rediscovery is our evidence that the capability is learned. The disclosed findings are in our advisories, and how we evaluate the model is on our methodology page.
Evaluate it on your workload
The honest way to compare is to measure. Bring the model you use today and a workload you cannot send out, and we will benchmark Basin against it inside an environment that matches your deployment constraints. Request an evaluation.